Pricing  Get Quote

User Policy Configuration

Help-desk-assisted Active Directory self-service

For businesses reeling under the effort and costs associated with help-desk-assisted account unlocks and password resets, self-service is a great solution, as it empowers end users to solve their own IT problems. However, some businesses stay away from deploying a self-service solution due to security concerns. For example, even though it is tedious for the help desk to maintain up-to-date profile information of every user in Active Directory, organizations may not allow end users to update their own profile information in Active Directory for fear of losing control over security and data consistency.

ADSelfService Plus, an identity security solution with MFA, SSO, and self-service password management capabilities, helps organizations maintain their security stance by enabling admins to review and approve users' self-service actions, such as updating their profile information or resetting their passwords.

Help desk software with an approval workflow feature, such as ADManager Plus, is required for the review and approval process. The approval workflow rules set by the admin in the help desk tool determine who can review and approve the self-service requests. In ADManager Plus, admins can create and modify any number of self-service approval workflow rules for different types of requests. For all self-service actions, admins verify users’ identities by configuring security questions based on Active Directory attributes. Once ADSelfService Plus is integrated with ADManager Plus, users' self-service actions are taken as requests instead of being directly updated in Active Directory.


Help-desk-assisted directory update and mail group subscription: How it works

  1. A user attempts to update their profile information or subscribe to a group. The user proves their identity to ADManager Plus by answering Active Directory-based security questions.
  2. A request for the self-service action is automatically created and sent to ADManager Plus (the workflow provider).
  3. A help desk technician reviews the request and approves it based on the workflow rules configured in ADManager Plus. Only the information that complies with the organization’s policies is approved.
  4. Once approved, the profile information or group subscription is automatically updated in Active Directory by the workflow engine or help desk software.
  5. The user can view the status of their request in the self-service portal. They can also be notified if their request is declined.

Help-desk-assisted self-service password reset and account unlock: How it works

By enabling an approval workflow for self-service password reset and account unlock actions, admins can give help desk technicians the ability to review and approve user activities. Identities are verified using a set of security questions based on Active Directory attributes, such as "What is your mobile number?" and "What is your department name?" Here’s how the approval workflow model works for self-service password reset and account unlock requests:

  1. A user clicks the Forgot your password? or Account locked down? buttons from the login screen of the web portal, the mobile app, or their login screen.
  2. The user is asked to verify their identity via the authentication techniques configured during their enrollment. The user is also required to answer Active Directory-based security questions to prove their identity to ADManager Plus.
  3. The user receives a pop-up saying that the request has been sent to a technician.
  4. After reviewing the request, the technician accepts or rejects it. If the request is accepted, the user receives a link via email.
  5. In the case of a password reset, the link takes the user to the Password Reset page where they can enter their new password. For an account unlock, the link takes them to the Unlock Account page where they can unlock their account after successfully verifying their identity.

Details like who created the request, who approved the request, and when the request was approved are recorded in reports for later use. Users can view the status of their request by logging in to the self-service portal of ADSelfService Plus.



Ensure security and consistency

Approval-based self-service gives admins control over users’ self-service actions and ensures that they are handled in a secure, consistent manner.


Significantly reduce IT service request calls

Users can create requests on their own without having to call the help desk. This significantly reduces the costs associated with users calling the help desk to submit IT service requests.


Enforce OU- and group-based policies

Admins can enforce a self-service approval workflow for one set of users based on their OU or group membership. That is, they have the option to give certain users, like those in the managers OU, a pure self-service experience by excluding them from self-service approval.

Mandate help desk or manager's approval for users' password

  • Please enter a business email id
  • US
  • By clicking 'Get Your Free Trial', you agree to processing of personal data according to the Privacy Policy.


Your download is in progress and it will be completed in just a few seconds!
If you face any issues, download manually here


Password self-service

Free Active Directory users from attending lengthy help desk calls by allowing them to self-service their password resets/ account unlock tasks. Hassle-free password change for Active Directory users with ADSelfService Plus ‘Change Password’ console. 

One identity with Single sign-on

Get seamless one-click access to 100+ cloud applications. With enterprise single sign-on, users can access all their cloud applications with their Active Directory credentials. Thanks to ADSelfService Plus! 

Password/Account Expiry Notification

Intimate Active Directory users of their impending password/account expiry by mailing them these password/account expiry notifications.

Password Synchronizer

Synchronize Windows Active Directory user password/account changes across multiple systems, automatically, including Office 365, G Suite, IBM iSeries and more. 

Password Policy Enforcer

Ensure strong user passwords that resist various hacking threats with ADSelfService Plus by enforcing Active Directory users to adhere to compliant passwords via displaying password complexity requirements.

Directory Self-UpdateCorporate Search

Portal that lets Active Directory users update their latest information and a quick search facility to scout for information about peers by using search keys, like contact number, of the personality being searched.

ADSelfService Plus trusted by

Back to Top